logo

APT37__2018__Red_Eyes_Hacking_Group_Report.pdf

ID: 9a3a5ea6-671e-4f7a-8dc1-b816a6af4b4b

STIX ID: report--9a3a5ea6-671e-4f7a-8dc1-b816a6af4b4b

Threat Score

88/100

Uploaded: 2026-08-14

Published Date: 2018-08-14

Last Modified Date: 2018-08-14

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
AhnLab's report documents a multi-year campaign by the Red Eyes actor (aka APT37/Group 123) targeting North Korea-related individuals and organizations using malicious Hangul/Office documents, mobile messenger lures, and exploitation of vulnerabilities including an Adobe Flash zero-day (CVE-2018-4878) and Hangul EPS; malware families include loaders (DocPrint/Reloader), Reloaderx (system enumeration and downloader), Redoor/DogCall backdoors, and destructive wipers, with numerous IoCs (MD5s, PDB strings, C2 URLs) and evidence suggesting ties to an earlier 2015 campaign (Operation ProgamsByMe).